Insufficient Validation in Bitdefender Update Server and BEST Relay Components
CVE-2020-15297

7.1HIGH

Key Information:

Vendor
CVE Published:
9 November 2020

What is CVE-2020-15297?

The vulnerability in Bitdefender's Update Server and BEST Relay components allows an unprivileged attacker to bypass existing mitigations, enabling unauthorized interaction with network hosts. This issue specifically impacts versions of Bitdefender Endpoint Security Tools released prior to 6.6.20.294. Users of these versions may face risks as the attacker gains the ability to execute unintended commands or access sensitive network resources.

Affected Version(s)

Bitdefender Update Server < 6.6.20.294

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.